WARNING: GRAPHIC IMAGES. The REvil ransomware operation has likely shut down after an unknown person hijacked their Tor payment portal and data leak blog. A threat actor affiliated with the REvil operation posted to the XSS hacking forum that someone hijacked the gang’s domains. The threat actor went on to say that they found no signs of compromise to their servers but will be shutting down the operation. The operation is likely to be rebranded as a new operation shortly, and we will likely see them rebrand as ‘REvil'”]

